Parent Spoof Bypass in Hulumi Policies for SecureBucket
CVE-2026-82861
8.7HIGH
What is CVE-2026-82861?
The Hulumi Policies library versions prior to 1.3.2 are susceptible to a parent spoof bypass vulnerability. This flaw allows malicious actors to submit counterfeit SecureBucket parent evidence during policy evaluations, enabling them to evade security policy assessments. As a result, the validation process may overlook unsafe configurations of buckets, potentially leading to unauthorized access or data exposure.
Affected Version(s)
policies 0 < 1.3.2
policies 1.3.2
